Insecure Direct Object Reference Vulnerability in MphRx's Minerva Product
CVE-2026-5780
8.5HIGH
What is CVE-2026-5780?
The vulnerability in MphRx's Minerva product allows authenticated users to exploit an insecure direct object reference (IDOR) in the '/minerva/moUser/show/' endpoint. By modifying the ID parameter, users can gain unauthorized access to the sensitive data of other registered users, potentially compromising user privacy and data integrity. This issue highlights the need for improved access control measures to safeguard personal information.
Affected Version(s)
Minerva 3.6.0
